Privacy Policy

Effective October 2, 2026

In short.

  • Yard stores what you put into it (canvases, notes, uploads, specs, chats) so your team can work on it, and nothing is sold or used for advertising.
  • Your code and files live on the runner that hosts your workspace and in the storage bucket your organization chooses. Both can be yours.
  • AI agents run with your own account at the agent's provider. What an agent reads is sent to that provider under your agreement with them.
  • Yard uses one session cookie to keep you signed in. There are no advertising or cross-site tracking cookies.

1. Who this policy covers

This policy explains how Yard ("Yard", "we", "us") handles personal information when you use the service at useyard.app and its API (the "Service"). It applies to people who create an account and to people invited into an organization.

Organizations decide what goes into their workspaces. For the content an organization puts into Yard, the organization is the controller and Yard processes it on the organization's behalf. For account and usage information, Yard is the controller.

If you run Yard yourself from the source code, the person or company operating that installation is responsible for it, and this policy does not apply to it.

2. What we collect

Information you give us

  • Account: your name, email address and a password, which is stored only as a salted hash (Argon2id).
  • Organization: its name, members, roles and invitations (including the email addresses you invite).
  • Workspace content: canvases, notes, links, uploaded files and images, specs, chat messages with agents, and the history of changes to them.
  • Source code: repositories you mount in a workspace are cloned onto the workspace's runner, together with the branches and changes made in projects.
  • Connections: if you connect GitHub, your GitHub user id, login, name, commit email and an access token; if you sign in to an AI agent, the credential files that agent's own sign-in produces; if your organization configures a storage bucket, its access keys.

Information collected as you use the Service

  • Session: a session identifier in a cookie, and when the session was created and last used.
  • Security and limits: IP addresses, kept for a short time to limit sign-in attempts and abuse.
  • Operation: server logs with request times, routes, status codes and errors. Tokens and credentials are removed from logs and from stored agent output.
  • Presence: while you have a workspace open, the other people in it see your name, cursor and selection. This is not stored.

We do not collect payment information at this time, and we do not buy information about you from others.

3. How we use it

  • to provide the Service: sign you in, show your workspaces, sync edits between collaborators, run the agents and projects you start, and make the pushes and pull requests you ask for;
  • to send you messages about your account and your work: verification codes, invitations, and notifications that a task finished or needs your input;
  • to keep the Service secure, prevent abuse, and find and fix faults;
  • to comply with law.

We do not use your content to train AI models, and we do not sell or rent personal information or use it for advertising. Where the law requires a legal basis, we rely on performing our contract with you, our legitimate interest in running a secure service, and your consent where we ask for it.

4. Where your content is kept

  • Runners. Workspace files, repositories, containers and terminals live on a runner. An organization can register its own runners (on its own servers or computers); content on those machines is under the organization's control, and Yard's servers relay it only to the people working in the workspace. Runners operated by Yard are operated by us.
  • Storage. Workspace files are backed up to an object storage bucket: one your organization configures (Cloudflare R2, Amazon S3 or Google Cloud Storage), or a bucket operated by Yard if you do not configure one.
  • Database. Accounts, organizations, chat messages and settings are kept in Yard's database.
  • Credentials. GitHub tokens, agent credentials and bucket keys are encrypted at rest (AES-256-GCM) and are never shown again after they are saved. They are sent to a runner only for the operation that needs them: a git command, or a single agent turn.

5. Who we share it with

  • Your organization. Members of an organization can see its workspaces according to their role, and its owners and admins manage membership.
  • AI agent providers. When you ask an agent to work, the agent's command-line tool runs inside a container on the runner and sends what it reads (prompts, the files and code it opens, its output) to the provider you signed in to, such as Anthropic, OpenAI or Cursor. This happens under your own account and that provider's terms and privacy policy. Review them before you connect an agent.
  • GitHub. When you connect GitHub, Yard reads the repositories you choose and, when you ask, pushes branches and opens or merges pull requests as you.
  • Infrastructure providers. Companies that host our servers, database and storage process data for us under contract and only on our instructions.
  • Legal and safety. We may disclose information when the law requires it or to protect the rights and safety of people and of the Service.
  • Business changes. If Yard is involved in a merger or sale, information may be transferred as part of it, and this policy continues to apply to it.

6. Cookies and local storage

Yard sets one cookie, yard_session, which keeps you signed in. It is only sent to Yard, cannot be read by scripts, and is deleted when you sign out. Your browser's local storage keeps interface preferences such as sidebar widths and your last agent choice. Yard does not use advertising cookies, cross-site trackers or third-party analytics.

7. How long we keep it

  • Workspace content is kept while the workspace exists. Archived workspaces and deleted projects are removed after your organization's retention period (30, 90 or 365 days, or kept until you delete them).
  • Account information is kept until you delete your account. Organization information is kept until an owner deletes the organization.
  • Sign-in attempt records are deleted within days; server logs within a limited period.
  • Content on runners and in buckets that your organization operates is kept or deleted by your organization.
  • Backups may hold deleted information for a short time before they expire.

8. Security

Each workspace runs as its own operating-system user and each task in its own container, without elevated privileges. Organizations are separated in every request. Passwords are hashed, credentials are encrypted, and sessions and tokens are stored only as hashes. No system is perfectly secure: use a strong, unique password, and share edit access to a workspace only with people you trust with its contents, since they can open a terminal in it.

9. Your choices and rights

  • You can see and change your profile, disconnect GitHub and remove agent accounts under Account.
  • You can ask us for a copy of your personal information, to correct it, to delete it, or to stop or restrict how we use it, and you can object to processing based on legitimate interests.
  • Depending on where you live (for example the EEA, the UK or California), you may have further rights, including data portability and the right to complain to your data protection authority.
  • For content that belongs to an organization, ask that organization first; we will help it respond.

To make a request, write to [email protected]. We do not discriminate against anyone for using these rights.

10. International transfers

Yard's servers and those of our providers may be in a different country from you. Where personal information is transferred across borders, we rely on safeguards the law recognises, such as standard contractual clauses. Content on runners and buckets your organization operates stays where your organization puts them.

11. Children

Yard is a tool for professional software work and is not directed at children under 16. We do not knowingly collect their information; if you believe a child has given us information, contact us and we will delete it.

12. Changes

If we change this policy in a way that matters, we will tell account holders by email or in the app before the change takes effect. The date at the top shows when it last changed.

13. Contact

Questions about privacy: [email protected]. See also the Terms of Service.